MALICIOUS — d32d2fc8713f7ae3123942de89aed7811c1946bb6c6805dc4db575d148c03fc7
MALICIOUS — d32d2fc8713f7ae3123942de89aed7811c1946bb6c6805dc4db575d148c03fc7 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100). 3 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d32d2fc8713f7ae3123942de89aed7811c1946bb6c6805dc4db575d148c03fc7 - SHA-1:
bcdd09032af52977704948b45f6427fb66be5d06 - MD5:
b9ce71c8ae925c192d8842c61e2eb144 - ssdeep:
3072:9ojjDv76DuqpAaI4y8x0DSjLz+6Qc15sFcOOT15FYg01lnepckvHAgJwHoW4ZBZU:9AFcC - TLSH:
T1D03B0806379516CF82988601EACC549CD8A07DEB9F11609BC7B5DE8DD81DB3244B9C8F - Submitted as: d32d2fc8713f7ae3123942de89aed7811c1946bb6c6805dc4db575d148c03fc7
- File type: html · Size: 108860 bytes
- Verdict: malicious (99/100)
Detections (3 of 54 engines)
- ClamAV feed: InterServer (malware): sigs.InterServer.net.HEX.Topline.js.malware.eval.string.fromcharcode.118.868.UNOFFICIAL
- Microsoft Defender: Trojan:HTML/Scrinject.B!bit
- Emsisoft (Emergency Kit): Trojan.Script.820489
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 9 weighted signals:
- ClamAV feed: InterServer (malware) flagged sigs.InterServer.net.HEX.Topline.js.malware.eval.string.fromcharcode.118.868.UNOFFICIAL (rule
sigs.InterServer.net.HEX.Topline.js.malware.eval.string.fromcharcode.118.868.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:HTML/Scrinject.B!bit (rule
Trojan:HTML/Scrinject.B!bit) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Script.820489 (rule
Trojan.Script.820489) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (layers: char-code) (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 17 external host(s) and 12 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://cdn.allyouwant.online/main.js?t=lrp1, http://gmpg.org/xfn/11, http://childcareowner.us/xmlrpc.php - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Extracted generic config (20 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
13837 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa.
- 252.0.0.224.in-addr.arpa.
- 209.52.40.23.in-addr.arpa.
- nexusrules.officeapps.live.com
- 146.109.171.150.in-addr.arpa.
- ecs.office.com
- desktop-hsgcbep
- update.googleapis.com
- self.events.data.microsoft.com
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 251.0.0.224.in-addr.arpa
Embedded URLs
- https://cdn.allyouwant.online/main.js?t=lrp1
- http://gmpg.org/xfn/11
- http://childcareowner.us/xmlrpc.php
- http://childcareowner.us/feed/
- http://childcareowner.us/comments/feed/
- http://childcareowner.us/wp-content/plugins/dpProEventCalendar/css/dpProEventCalendar.css?ver=2.9.8
- http://childcareowner.us/wp-content/plugins/dpProEventCalendar/css/font-awesome.css?ver=2.9.8
- http://childcareowner.us/wp-content/plugins/gamipress/assets/css/gamipress.min.css?ver=1.5.8.2
- http://childcareowner.us/wp-content/plugins/revslider/public/assets/css/settings.css?ver=5.4.6.3.1
- http://childcareowner.us/wp-content/plugins/sfwd-lms/assets/css/style.min.css?ver=2.3.3
- http://childcareowner.us/wp-content/plugins/sfwd-lms/assets/css/front.min.css?ver=2.3.3
- http://childcareowner.us/wp-content/plugins/sfwd-lms/assets/css/jquery.dropdown.min.css?ver=2.3.3
- http://childcareowner.us/wp-content/themes/boss/learndash/learndash_template_style.min.css?ver=2.3.3
- http://childcareowner.us/wp-content/plugins/wise-chat/css/wise_chat.css?ver=4.9.18
- http://childcareowner.us/wp-content/plugins/woocommerce/assets/css/woocommerce-layout.css?ver=3.4.8
- http://childcareowner.us/wp-content/plugins/woocommerce/assets/css/woocommerce-smallscreen.css?ver=3.4.8
- http://childcareowner.us/wp-content/plugins/woocommerce/assets/css/woocommerce.css?ver=3.4.8
- http://childcareowner.us/wp-content/plugins/wp-knowledgebase/template/kbe_style.css?ver=1.1.8
- http://childcareowner.us/wp-content/plugins/badgeos/css/badgeos-single.css?ver=1.0.1
- http://childcareowner.us/wp-content/plugins/eonet-frontend-publisher/core/assets/css/eonet_ui_frontend.min.css?ver=4.9.18
- http://childcareowner.us/wp-includes/css/dashicons.min.css?ver=4.9.18
- http://childcareowner.us/wp-includes/css/editor.min.css?ver=4.9.18
- http://childcareowner.us/wp-content/plugins/eonet-frontend-publisher/component-frontend-publisher/assets/css/eonet-frontend-publisher-style.min.css?ver=4.9.18
- http://childcareowner.us/wp-content/plugins/eonet-live-search/component-live-search/assets/css/eonet-live-search-style.min.css?ver=4.9.18
- http://childcareowner.us/wp-content/plugins/eonet-project-manager/component-project-manager/assets/css/eonet-project-manager-style.min.css?ver=4.9.18
Embedded domains
- cdn.allyouwant.online
- gmpg.org
- childcareowner.us
- cdn.ckeditor.com
- fonts.googleapis.com
- maxcdn.bootstrapcdn.com
- s.w.org
- api.w.org
- a.to
- status.in
- lesson-status.in
- span.name
- childcareowner.biz
- www.w3-edge.com
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 1.5.8.2
- 5.4.6.3
- 1.7.9.6
- 3.9.6.1
- 2.0.1.2
- 40.84.97.4
- 52.123.128.14
- 52.178.17.235
- 72.145.35.103
- 72.145.35.97
- 52.148.114.188
- 172.172.255.218
- 20.42.179.204
- 20.184.175.1
- 52.168.117.174
- 172.172.255.216
- 74.178.76.44
- 172.215.188.232
- 57.155.101.212
- 48.211.4.16
- 40.84.85.40
- 57.154.63.210
- 52.123.129.14
- 4.144.132.223
- 52.123.252.218
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report